mediumCVSS 7.3Vulnerability

CVE-2026-5842

A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 0.3.75 is sufficient to resolve this issue. It is suggested to upgrade the affected component.

Properties

severity
medium
summary
decolua 9router vulnerable to authorization bypass
epss_score
0.00313
cvss_score
7.3
ghsa_published
2026-04-09T06:30:28Z
source_url
https://github.com/advisories/GHSA-xrrh-p7f2-27vm
ghsa_updated
2026-04-10T19:20:28Z
ghsa_id
GHSA-xrrh-p7f2-27vm
cve_id
CVE-2026-5842
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
false
epss_percentile
0.24125

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/9router

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/9router

HAS_WEAKNESS (1)

[Weakness]Improper Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5842 (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal